The US National Vulnerabilities Database has recorded 45,207 software security flaws through 2026, tracking toward roughly double the total documented in 2025.
The surge in documented vulnerabilities reflects an accelerating trend in software security threats. With nearly half the year remaining, the current pace suggests 2026 will substantially exceed previous vulnerability records.
The National Vulnerabilities Database tracks publicly disclosed flaws across major software products and platforms. These flaws range in severity from minor issues to critical exploits that enable unauthorized system access.
The doubling rate raises questions about whether the increase stems from improved detection methods, more rigorous disclosure practices, or a genuine proliferation of security weaknesses. Software complexity continues expanding, with interconnected systems and dependencies creating additional attack surfaces.
Industry experts have long flagged the growing gap between vulnerability discovery and remediation timelines. As flaw counts accelerate, organizations face mounting pressure to patch systems faster and prioritize critical vulnerabilities among competing priorities.
The data underscores the mounting challenge facing security teams worldwide as software continues to permeate critical infrastructure and daily operations.
A new Atlantic investigation reveals the extent of AI-powered surveillance through wearable devices and countermeasures being developed to combat constant recording.
A security researcher has developed an algorithm that generates computer-generated patterns capable of evading detection by surveillance cameras. The technique can hide people, faces, and vehicles from AI-powered monitoring systems.
Scammers are enrolling fake students at US community colleges, using artificial intelligence to complete coursework, and collecting financial aid payouts. The scheme exploits gaps in enrollment verification and assignment monitoring.
The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.